North Korean authorities recently arrested several ex-cyber operatives and IT experts accused of hacking into two major state banks and laundering stolen funds through cryptocurrency channels. This incident marks a rare shift, with cyberattacks targeting institutions within North Korea itself rather than foreign victims.

Details of the Internal Cybercrime Operation

According to reports from South Korean outlet Daily NK, the suspects breached the internal networks of North Korea's central bank and the Foreign Trade Bank, key financial hubs for the regime. They converted stolen assets into digital currencies and funneled them via brokers operating out of China. While Cointelegraph could not independently confirm these claims, the pattern matches previous cases involving North Korean cybercriminals who often exploit cryptocurrency to mask illicit transfers.

The case stands out because, unlike the typical external hacks against international platforms, the targets here were domestic. Past incidents involved schemes against foreign exchanges or DeFi protocols, but now the theft happened from the North Korean government’s own reserves.

North Korea’s Growing Cybercrime Footprint and Reactions

For over ten years, North Korea has been linked to some of the largest digital heists globally. The notorious Lazarus Group, tied to the regime’s intelligence, pulled off a $620 million robbery of the Ronin Network bridge in 2022 and followed up with a $1.5 billion heist on the Bybit platform in early 2025. U.S. Treasury officials estimate the regime earns between $1 billion and $2 billion annually from cyber operations. These funds support North Korea's missile programs and help bypass international sanctions.

In fact, blockchain analytics firm Chainalysis attributed 76% of global cryptocurrency thefts in 2026 to entities connected with North Korea. The internal theft case reported by Daily NK adds a new layer to the understanding of Pyongyang’s cyber tactics. It also follows revelations earlier this year that a developer linked to North Korea had infiltrated Consensys, the company behind the MetaMask wallet.

The continuous exposure of these hacking schemes keeps spotlighting North Korea's evolving cyber capabilities, putting pressure on international authorities to tighten scrutiny of crypto transactions linked to the regime.